Industry News
Four Deals, One Signal: Email Authentication Is Consolidating Into the Platform Players
September 17, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Four acquisitions in roughly three years have quietly redrawn the map of who sells email authentication. A certificate authority bought a zero trust DMARC company. A legacy email security giant bought a European Microsoft 365 specialist for $1.8 billion. A security awareness training vendor bought an AI-driven email protection firm. A network edge company bought a phishing-defense startup to round out its zero trust stack. None of these companies set out to be "the DMARC vendor." That is exactly the point.
The pattern across all four deals is simple: email authentication, once sold as a standalone category, is being absorbed into broader identity, security, and MSP-facing platforms. For managed service providers, this means the tools used to monitor SPF, DKIM, and DMARC for client domains are increasingly bundled features inside larger suites rather than dedicated products, which changes how those tools get priced, supported, and eventually discontinued.
What Are the Four Deals?
Each deal targeted a different kind of platform, but the acquired company did the same job: authenticate outbound mail and stop domain spoofing. Together they cover digital trust infrastructure, enterprise email security, security awareness training, and network edge security.
- DigiCert acquired Valimail in September 2025, describing the move as a way to establish zero trust email authentication as a new DigiCert ONE capability alongside its existing certificate and PKI business, and framing DMARC as a market worth more than $4 billion.
- Proofpoint completed its acquisition of Hornetsecurity in December 2025 for $1.8 billion. Hornetsecurity brought nearly $200 million in annual recurring revenue with 20% year-over-year growth, and Proofpoint has been explicit that the deal is meant to increase its options for managed service providers, an audience it previously served less directly.
- KnowBe4 acquired Egress in 2024 to fold AI-driven email security detection into a platform built around security awareness training, a deal SecurityWeek covered as part of a broader shift toward combining human-risk training with technical email defenses.
- Cloudflare acquired Area 1 Security in 2022 for approximately $162 million, bringing pre-emptive phishing defense into its Zero Trust network so that email security became a native part of Cloudflare's platform rather than a bolt-on.
Why Is This Happening Now?
Two forces are converging: regulatory-style pressure from the largest inbox providers, and a cybersecurity M&A market that rewards recurring revenue over point-solution novelty. Both make an independent DMARC vendor a more attractive acquisition target than a durable standalone business.
Since February 2024, Google has required that bulk senders sending more than 5,000 messages a day to Gmail accounts set up SPF, DKIM, and DMARC for their sending domains, with Yahoo enforcing comparable rules on a similar timeline. That mandate turned DMARC from a niche security control into baseline plumbing that every organization sending marketing or transactional email now needs, which made authentication tooling suddenly relevant to a far larger buyer base than the security teams who cared about it a decade ago.
At the protocol level, DMARC itself matured this year. The IETF published RFC 9989 as the new DMARC specification, moving the protocol onto the Standards Track and formally obsoleting the original RFC 7489 from 2015. A protocol graduating to full IETF standard status tends to signal that a technology has moved from experimental to mandatory infrastructure, and mandatory infrastructure is exactly what platform vendors want to own rather than integrate with.
Layered on top of that, 2025 was a heavy year for cybersecurity dealmaking generally. SecurityWeek's annual tracker counted 426 cybersecurity M&A deals in 2025, with the market favoring mature, revenue-generating targets over early-stage startups. Email authentication vendors with real customer bases and predictable renewal revenue fit that profile precisely.
What Does Consolidation Mean for MSPs?
For MSPs, consolidation means the authentication tool sitting inside a client's security stack today may be owned by a different, larger company within a year or two, often with a different pricing model, support tier, or roadmap. That is not automatically bad. It can mean better integration with the platforms MSPs already run, but it also means less predictability about how a formerly standalone tool will be packaged tomorrow.
The Proofpoint-Hornetsecurity deal is the clearest MSP-facing example. Hornetsecurity built a partner program specifically for managed providers, and Proofpoint's own messaging around the acquisition promises to bring the Hornetsecurity platform to MSP partners globally while increasing investment in that partner program. That is a reasonable near-term outcome. It is also a reminder that an MSP's authentication tooling now depends on a much larger company's strategic priorities, not just the roadmap of the team that originally built the product.
<br>| Before consolidation | After consolidation |
|---|---|
| Standalone DMARC vendor, single-purpose pricing | Authentication bundled inside a platform suite |
| Roadmap driven by a focused product team | Roadmap driven by parent company's broader strategy |
| Support tied to a niche specialist | Support routed through a larger, tiered organization |
| Easy to swap for another point tool | Harder to separate from adjacent platform features |
Is Standalone DMARC Tooling Going Away?
Not entirely, but the space for it is narrowing. Independent vendors still exist and still serve MSPs well, but four acquisitions across four very different platform categories in three years suggests the direction of travel is toward bundling, not fragmentation.
That shift raises a practical question for any MSP evaluating tools today: does the authentication and domain-monitoring layer need to live inside a single giant suite, or can it stay independent and interoperable regardless of who owns the mailbox security stack next year? A platform-agnostic scanning layer that reports on SPF, DKIM, and DMARC posture across every client domain avoids tying an MSP's visibility to the acquisition calendar of any one vendor.
How Should MSPs Respond to the Shift?
The practical response is to separate domain-authentication visibility from whichever mailbox security suite a client happens to run. Monitoring SPF, DKIM, and DMARC posture is a different job than filtering inbound mail, and treating them as one bundled purchase means losing visibility every time the underlying vendor gets acquired.
MSPs that want a straightforward starting point can review current authentication coverage across every client domain using a tool built specifically for that job rather than one absorbed into a larger suite as a secondary feature. Comparing plans on the pricing page makes it easier to see what that kind of independent visibility actually costs at scale, and the getting-started guide walks through the setup for teams managing dozens or hundreds of domains at once. For MSPs ready to test that approach against their current client list, the fastest path is to sign up and run a first scan.
The Bottom Line
Four deals do not prove that standalone email authentication tooling will disappear, but they do describe a consistent direction: the biggest platforms in digital trust, enterprise email, security awareness, and network edge security all decided the fastest way to offer authentication was to buy a company that already built it. MSPs do not need to predict the next acquisition to protect themselves from it. They need domain-level visibility that does not depend on which company owns the underlying tool next quarter.